If you work with the Department of Defense, you’ve likely heard that the DoD put a major piece of its cybersecurity certification program on hold. The headlines are creating confusion, and understandably so. Words like “suspended” and “paused” can sound like a hall pass. They’re not. Here’s what actually happened, what it means for your business, and what you should do right now.
A Quick Recap: What is CMMC?
CMMC – the Cybersecurity Maturity Model Certification – is the DoD’s framework for ensuring that defense contractors and their partners have real cybersecurity protections in place for sensitive government information. It rolls out in phases, with Phase 2 being the stage that required mandatory third-party audits by an accredited assessor. That phase was set to go into effect on November 10, 2026.
What Just Changed
On July 13, 2026, the DoD announced the immediate suspension of CMMC Phase 2 – along with all future implementation milestones.
There were two compounding problems driving this decision. First, Phase 2 was generating costs and administrative burdens so significant that smaller and mid-sized businesses were being pushed out of the defense supply chain. That’s the opposite of what the program was designed to do. The DoD relies on a broad, competitive supplier base to keep pace with adversaries – shrinking that base in the name of security was seen as a strategic liability.
Second, the DoD’s own CIO put it plainly: there simply weren’t enough accredited auditors to certify the number of companies that needed it before the deadline.
To address this, the DoD launched a CMMC Reform Task Force – a 60-day top-to-bottom review of the entire program. The task force has three priorities:
- Cutting compliance costs, especially for small and mid-sized businesses
- Making the program more scalable and realistic to implement
- Replacing administrative burden with security measures that actually protect data
The task force is expected to deliver its recommendations in Fall 2026, after which a revised CMMC Phase 2 framework will be released.
What This Does NOT Mean
This is the part that matters most – and the part that’s easiest to misread.
The pause applies to the certification process. Your security obligations did not change.
Here is exactly what is still fully active and enforceable:
- Phase 1 self-assessments are still required. You must complete your annual self-assessment, submit your score to the SPRS database, and file your annual affirmation. Nothing about that has changed.
- DFARS 252.204-7012 – the contract clause requiring you to protect covered defense information – is still in your contracts. The DoD was explicit: “This action does not eliminate the requirement for companies to protect federal data.” (war.gov official press release, July 13, 2026)
- NIST SP 800-171 – the technical standard that defines what cybersecurity compliance actually looks like – remains the active benchmark you’re measured against.
- Government-led spot assessments can still happen. The DoD’s assessment center retains the authority to audit contractors directly – particularly those with unusually high self-assessment scores, those handling sensitive technology, or those flagged by a complaint or whistleblower.
- The False Claims Act still applies – Submitting an inaccurate self-assessment score is not a paperwork issue – it’s a legal one. The Department of Justice has been actively pursuing cases under its Civil Cyber-Fraud Initiative, and that enforcement posture has not changed.
The bottom line: threat actors targeting the defense supply chain didn’t pause when they read the press release. Your contractual obligations didn’t either.
What You Should Do Right Now
Whether you were actively working toward CMMC certification or just watching the deadline, here’s how to use this window wisely.
Keep Moving on NIST SP 800-171
Phase 1 self-assessments are still live. That means the required cybersecurity controls – multi-factor authentication, access management, incident response, and more – are still mandatory. Don’t let your momentum stall.
Make Sure Your SPRS Score is Accurate
Contracting officers verify your self-assessment score in the SPRS database before awarding contracts. An inflated or outdated score doesn’t just hurt your credibility – it creates real legal exposure under the False Claims Act. If your score doesn’t reflect your current posture, now is the time to fix it.
If You Were Mid-Assessment, Consider Finishing It
If your organization was already working through a third-party assessment, stopping now may cost more than it saves. A verified, well-documented security posture is a genuine competitive differentiator right now – and when the reformed framework drops, companies with that posture already in place will move faster and more confidently than those starting from scratch.
Watch for the Reform Task Force Report
The 60-day review window runs through approximately mid-September 2026. Expect the revised CMMC Phase 2 framework to lean more heavily on self-attestation and commercial security tools, and to be more accessible for smaller businesses. When the report drops, you’ll want to be positioned to act quickly – not scrambling to catch up.
The Bottom Line
The headline says “suspension.” The reality is more nuanced.
For businesses that have already done the work, this is a moment to hold your position. Your investment isn’t wasted – it’s a head start. You have a clean SPRS score, documented security controls, and a defensible posture. That is a competitive advantage right now, and it will be when the new framework launches.
CMMC Phase 2 isn’t going away. It’s being rebuilt to work better. The security obligation underneath it never changed.
Not sure where your business stands? We help defense contractors and their partners meet CMMC Level 1 requirements – from identifying gaps in your current controls to making sure your SPRS score accurately reflects where you stand. Contact us and let’s make sure you’re covered.




